On May 1, 2012, an unencrypted laptop belonging to a University of Kentucky HealthCare employee was stolen after a workforce member's son borrowed it without permission, knowing the computer's password. The PHI of approximately 4,488 individuals was exposed, including medical record numbers, dates of visits, and chief complaints. The covered entity notified HHS, the media, and affected individuals, revised its HIPAA and mobile device policies, implemented risk-based security measures, and provided employee training. The responsible workforce member ultimately resigned. OCR obtained assurances that all corrective actions were completed. Location of breached info: Laptop.
Affected (this filing): 4,490